Close Menu
Computing.net
    Facebook X (Twitter) Instagram
    Computing.netComputing.net
    • News
      1. AI
      2. Crypto
      3. Gaming
      4. Hardware
      5. Security
      6. Software
      7. View All

      Anthropic’s COBOL Automation Tool Triggers IBM Stock Plunge and Crypto Market Decline

      February 24, 2026

      AI Trading Bot Loses $441K in Crypto After Decimal Point Mistake

      February 23, 2026

      Tesla (TSLA) Stock: Goodbye Sedans, Hello Robots in Dramatic Production Shift

      January 29, 2026

      Palantir Technologies (PLTR) Stock: Why Bears May Be Wrong About Valuation Concerns

      January 29, 2026

      SUI Token Rallies 40% Following Major Staking Event and CME Futures Announcement

      May 12, 2026

      Chainlink (LINK) Surges to $10.40 as Network Activity Hits Eight-Month Peak

      May 12, 2026

      Dogecoin Whales Ramp Up Accumulation as DOGE Eyes Critical Breakout Levels

      May 12, 2026

      Bitcoin Holds $81K While Burry Flags Nasdaq Bubble and Oil Surges Past $105

      May 12, 2026

      Hamster Kombat: Unraveling TON’s Gaming Phenomenon

      August 7, 2024

      W-Coin: Exploring the Latest Telegram Tap-to-Earn Phenomenon

      August 7, 2024

      Hamster Kombat: 300 Million Players & Counting, HMSTR Token Airdrop Soon!

      July 31, 2024

      Hamster Kombat Developers Work with TON Team on Airdrop Solution

      July 30, 2024

      Nothing Expands Product Line with New AI Feature & Phone Update

      July 31, 2024

      Security Audit Reveals Concerns in Atari’s Blockchain Game on Base

      August 6, 2024

      SideWinder Group Targets Maritime Facilities in New Cyber Espionage Campaign

      July 30, 2024

      OAuth Implementation Flaw Exposes Millions of Websites to XSS Attacks

      July 30, 2024

      Hamster Kombat Players Face Growing Cybersecurity Threats

      July 25, 2024

      Anthropic’s COBOL Automation Tool Triggers IBM Stock Plunge and Crypto Market Decline

      February 24, 2026

      Cookie Crumble: Google Halts Plans to Eliminate Third-Party Cookies in Chrome

      July 23, 2024

      Big Brother is Watching: Apple’s Creepy New Ad Urges iPhone Users to Ditch Chrome

      July 23, 2024

      Nvidia Stock Soars to New Record at $219.44 Ahead of May 20 Earnings

      May 12, 2026

      Rocket Lab Shares Surge Past $120 Following Wave of Analyst Upgrades

      May 12, 2026

      GM Shares Decline Following 600 IT Layoffs Amid Strategic AI Workforce Transformation

      May 12, 2026

      SES Delivers €847M Q1 Performance as Intelsat Integration and Aviation Deals Fuel Expansion

      May 12, 2026
    • How To

      Batch Files: Tokens and Delimiters (FOR Loops)

      July 31, 2024

      Types of Ethernet Cabling & Electrical Low Voltage Wiring

      July 9, 2024

      What You Should Know About .JSON File Extension

      January 10, 2023

      Bkup File Extension

      November 19, 2022

      HEIC File Extension

      November 19, 2022
    • Office
      1. Excel
      2. Google Sheets
      3. View All

      How to Convert Column List to Comma Separated List in Excel

      July 24, 2024

      How to Find the Last Monday of the Month in Excel

      July 24, 2024

      Convert Bytes to MB or GB in Excel: 3 Methods!

      July 24, 2024

      How to Remove Characters from Right in Excel

      July 30, 2023

      How to Subtract in Google Sheets: Complete Guide

      July 31, 2024

      Bullet Points in Google Sheets

      January 20, 2022

      Sort by Date in Google Sheets

      January 18, 2022

      Google Sheets Timestamp

      January 17, 2022

      How to Subtract in Google Sheets: Complete Guide

      July 31, 2024

      How to Convert Column List to Comma Separated List in Excel

      July 24, 2024

      How to Find the Last Monday of the Month in Excel

      July 24, 2024

      Convert Bytes to MB or GB in Excel: 3 Methods!

      July 24, 2024
    • Answers
    • About
    • Contact
    Facebook X (Twitter)
    Computing.net
    News

    Malicious AI Routers Target Cryptocurrency Developer Credentials

    Oliver DaleBy Oliver DaleApril 13, 2026
    Twitter LinkedIn Email Telegram
    Twitter LinkedIn Email Telegram

    Contents:

    Toggle
    • Key Findings
    • Automated Execution Amplifies Vulnerability
    • Security Recommendations

    Key Findings

    • University of California study identified 26 third-party LLM routers engaging in credential theft and malicious code injection
    • Researchers witnessed Ether withdrawn from a test wallet by a compromised router
    • These routing services can read all transmitted messages in plaintext, exposing private keys and recovery phrases
    • An automated execution feature called “YOLO mode” enables AI agents to run instructions without requiring user approval
    • Security experts advise completely avoiding the transmission of private keys through AI agent platforms

    A team from the University of California has uncovered evidence that certain third-party artificial intelligence routing platforms pose significant security risks by harvesting cryptocurrency credentials and inserting harmful code into development environments.

    26 LLM routers are secretly injecting malicious tool calls and stealing creds. One drained our client $500k wallet.

    We also managed to poison routers to forward traffic to us. Within several hours, we can directly take over ~400 hosts.

    Check our paper: https://t.co/zyWz25CDpl pic.twitter.com/PlhmOYz2ec

    — Chaofan Shou (@Fried_rice) April 10, 2026

    The research team released their findings this week in a comprehensive paper examining what they termed “malicious intermediary attacks” targeting the large language model (LLM) infrastructure ecosystem.

    These LLM routing services function as intermediary platforms positioned between developers and major AI providers such as OpenAI, Anthropic, and Google. Their primary role involves managing and directing API requests across various service providers.

    The security vulnerability arises because these routing platforms terminate encrypted connections. This architecture grants them complete, unencrypted visibility into every communication that passes through their systems.

    Developers utilizing AI-powered coding assistants such as Claude Code for building smart contracts or cryptocurrency wallet applications may unknowingly transmit private keys and seed phrases through these intermediary services.

    The research team evaluated 28 commercial routing services and 400 free alternatives collected from online developer communities.

    Results revealed nine routers actively inserting malicious code, two employing sophisticated evasion techniques, and 17 capturing researcher-controlled Amazon Web Services authentication credentials.

    One routing service successfully withdrew Ether from a deliberately created decoy wallet. The financial impact of this incident totaled less than $50.

    According to the researchers, distinguishing between legitimate credential processing and actual theft presents an almost insurmountable challenge for users, given that routers already possess plaintext access to sensitive information as part of their core functionality.

    Automated Execution Amplifies Vulnerability

    The published paper highlighted a configuration option present in numerous AI agent frameworks known as “YOLO mode.” When enabled, this setting allows an AI agent to carry out commands automatically, bypassing individual user authorization for each action.

    This configuration dramatically increases security exposure. When a router introduces malicious directives, YOLO mode enables those directives to execute without any human oversight.

    The research team also discovered that routing services with previously clean security records can transition to malicious behavior without operators detecting the change. Free routing services, specifically, may leverage discounted API pricing as bait to attract users while covertly extracting credentials.

    Security Recommendations

    The research team urged developers to implement robust client-side security measures and completely avoid transmitting private keys or seed phrases within AI agent sessions.

    For sustainable protection, the researchers proposed that AI companies implement cryptographic signing for their responses. This would enable developers to authenticate that instructions received by an agent genuinely originated from the designated model.

    Co-author Chaofan Shou shared on X that “26 LLM routers are secretly injecting malicious tool calls and stealing creds.”

    The research team emphasized that LLM API routing services occupy a crucial trust position that the wider AI industry presently assumes to be secure without verification.

    The published paper did not include specific details such as blockchain transaction identifiers for the compromised wallet incident.

    Share. Twitter LinkedIn Email Telegram
    Oliver Dale
    • Website
    • X (Twitter)
    • LinkedIn

    Editor-in-Chief of Computing.net and founder of Kooc Media, A UK-Based Online Media Company. Believer in Open-Source Software, Blockchain Technology & a Free and Fair Internet for all. His writing has been quoted by Nasdaq, Dow Jones, Investopedia, The New Yorker, Forbes, Techcrunch & More. Contact Oliver@blockonomi.com

    Related Posts

    Senate Releases Complete Clarity Act Text: Crypto Regulation Bill Faces Critical Vote

    May 12, 2026

    Bitcoin Holds $81K While Burry Flags Nasdaq Bubble and Oil Surges Past $105

    May 12, 2026

    Binance AI Systems Thwart $10.5 Billion in Cryptocurrency Fraud Attempts Over 15 Months

    May 12, 2026

    Galaxy Digital Partners with Sharplink on $125M Ethereum DeFi Yield Strategy

    May 12, 2026

    Kiyosaki’s 2026 Economic Forecast: His Investment Strategy for Silver, Bitcoin and Ethereum

    May 12, 2026

    Brent Crude Surges Past $100 Following Trump’s Dismissal of Iran Proposal

    May 11, 2026
    Add A Comment

    Comments are closed.

    Latest

    Nvidia Stock Soars to New Record at $219.44 Ahead of May 20 Earnings

    May 12, 2026

    Rocket Lab Shares Surge Past $120 Following Wave of Analyst Upgrades

    May 12, 2026

    GM Shares Decline Following 600 IT Layoffs Amid Strategic AI Workforce Transformation

    May 12, 2026

    SES Delivers €847M Q1 Performance as Intelsat Integration and Aviation Deals Fuel Expansion

    May 12, 2026

    Trump Dismisses Iran Peace Proposal — Oil Markets React as Hormuz Remains Restricted

    May 12, 2026
    • Facebook
    • Twitter

    Latest Reviews

    Meta Platforms Shares Tumble 8% Despite Strong Q1 Performance Amid AI Investment Surge

    April 30, 2026

    Flush.com Review: Casino & Sportsbook With 275% Welcome Bonus

    March 7, 2026

    Katsubet Review: Crypto Casino With 300% Welcome Bonus & Free Spins

    March 7, 2026

    7Bit Review: Crypto Casino With 325% Bonus & 250 FS

    March 7, 2026

    Mega Dice Review: Crypto Casino With 200% Bonus & 50 Free Spins, Legit?

    March 7, 2026


    Home / Privacy Policy / Terms & Conditions

    Computing.net © 1996 - 2026 Kooc Media Ltd. All rights reserved. Registered Company No.05695741

    Type above and press Enter to search. Press Esc to cancel.